Session Type: Full-Day Seminar
This seminar will discuss fundamental security principles, such as confidentiality, integrity, and availability and how they apply to Web-based applications. We will briefly explore technical aspects of the Web and HTTP (cookies, HTTP headers, and the stateless nature of the Web) and see how these affect application security.
The main focus will be a detailed exploration of the Open Web Application Security Project's (OWASP) top-10 list of Web application vulnerabilities. We will discuss these threats in detail, give specific examples, and explain how to secure your applications against them. We will also discuss threat modeling and software development practices that will help create secure applications and demonstrate a variety of tools to aid in the testing and scanning of applications.